Research Archive

APT Analysis

Browse entries by research type, time, topic, and threat domain. This page behaves more like an archive than a feed.

2025

Over a near-black teal-blue background, a weaponized legitimate analytics pipeline silently exfiltrates sensitive mnemonic data disguised as anomaly event fields; foreground: a dark door sprung open from a version-update package with copper-orange light leaking through the seams; midground: an APT silhouette straddling a multi-stage arrow staircase, a phased timeline, and a smoking trust-chain link; background: a leather wallet with glowing cracks and an anomalous cube hovering over a glass panel; corner: a copper-orange low-poly Trust Wallet shield logo — symbolizing the APT-level targeted supply chain attack that exfiltrated mnemonics via the PostHog channel in the v2.68 backdoor
Security Research

Trust Wallet Extension Backdoor: v2.68 Malicious Code Injection Analysis

In December 2025, Trust Wallet Browser Extension v2.68 was found to contain malicious backdoor code. The attacker modified the extension's source to exfiltrate users' seed phrases and private keys to the malicious domain metrics-trustwallet.com. This article dissects the malicious code and reconstructs the attack chain, concluding that this is an APT-level targeted supply chain attack.

2025-12-26 4 min #Supply Chain Attack
Over a near-black teal-blue background, a hooded APT silhouette ascending a multi-stage arrow staircase, a PyYAML RCE backdoor glowing copper-orange at the entry point, lateral-movement arrows threading toward a wallet server, and a smoking trust-chain link — symbolizing the Lazarus Group's targeted APT attack on cryptocurrency exchanges
Security Research

Lazarus Group APT Attack on Cryptocurrency Exchanges: IOC & TTP Disclosure

After nearly a month of forensic investigation into multiple cryptocurrency exchange breaches, I and 23pds confirmed the attacker as Lazarus Group. This article discloses the complete set of IOCs and TTPs, including social engineering entry, PyYAML RCE backdoor deployment, and lateral movement to wallet servers.

2025-02-23 7 min #APT Analysis